SIDH with masked torsion point images

Authors: Tako Boris Fouotsa


We propose a countermeasure to the Castryck-Decru attack on SIDH. The attack heavily relies on the images of torsion points. The main input to our countermeasure consists in masking the torsion point images in SIDH in a way they are not exploitable in the attack, but can be used to complete the key exchange. This comes with a change in the form the field characteristic and a considerable increase in the parameter sizes.

ePrint: https://eprint.iacr.org/2022/1054

Talk by T.Moriya and TB.Fouotsa at the isogeny days in Leuven.

Slides of a talk given at IRMAR Rennes by the author.